windows-kernel topic
AtomicSyscall
Tools and PoCs for Windows syscall investigation.
PrivFu
Kernel mode WinDbg extension and PoCs for token privilege investigation.
NtRays
Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.
kHypervisor
kHypervisor is a lightweight bluepill-like nested VMM for Windows, it provides and emulating a basic function of Intel VT-x
SimpleSvmHook
SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.
SimpleSvm
A minimalistic educational hypervisor for Windows on AMD processors.
DriverBuddyReloaded
Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks
HyperWin
A native hypervisor designed for the Windows operating system
SharpWnfSuite
C# Utilities for Windows Notification Facility
Kernel-Memory-Reading-Writing
🔍 Code to read / write the Process Memory from the Kernel 🔧